In international cloud and hosting selection, network performance is often the key bottleneck for availability and response latency. Yet many engineers and administrators who buy instances advertising 1Gbps or faster ports find high speed-test results alongside sluggish production behavior. This guide establishes a standardized, engineering-based, reproducible framework for cross-border VPS network evaluation, clarifying the relationship between port bandwidth, concurrent streams, and route quality. It explains how to avoid misleading multi-thread test results and collect reliable baseline data under demanding evening peak conditions.
One. Separating Key Metrics and Understanding Physical Models in International Network Speed Testing#
When evaluating a cross-border server, download speed alone cannot describe network quality. International public-network transfers typically involve high latency and a large Bandwidth-Delay Product (BDP). Distinguish these core metrics:
┌── 物理接口带宽 (Interface Capacity) ── 虚拟网卡硬件限速(如 500Mbps、1Gbps、2.5Gbps)
├── 骨干网 QoS 调度与传输优先级 ────── 电信 CN2 GIA/163、联通 9929/4837、移动 CMIN2/CMI
网络质量多维模型 ──┼── 单线程吞吐量 (Single-Thread) ───── 单一 TCP 流承载能力(真实业务、API、Web 加载核心)
├── 多线程并发吞吐 (Multi-Thread) ──── 多连接聚合跑满端口能力(掩盖丢包的常见陷阱)
└── 时延抖动与拥塞丢包率 (RTT & Loss) ─ 路由物理距离决定的基础时延与出口拥塞导致的丢包1. 单线程吞吐量:检验 Networks 成色的唯一硬指标#
- 生产场景的本质是单流交互:网页静态 resources 拉取、API 远程调用、 Databases 同步、SSH 终端响应以及多数即时传输协议,均工作在单一 TCP 连接或有限连接上。
- TCP Congestion Control and Multiplicative Halving After Packet Loss:传统拥塞控制算法(如 Cubic)在检测到丢包事件时,会主动将拥塞窗口(CWND)压缩。在跨国 150ms~250ms 的高 RTT 链路中,即使仅有 1%~2% 的持续丢包,单一 TCP 连接也无法顺利扩大窗口,导致单线程速度暴跌至数兆以内。
- The Dividing Line in Evaluations:普通国际 Networks 在闲时虽然多线程可以跑满,但晚高峰单线程往往断崖式下跌;而在 BandwagonHost( BandwagonHost )高质量机房(如 DC6/DC9 的 CN2 GIA 架构)或 DMIT 的 Premium/Pro 高优先级路由下,晚高峰单线程仍能维持 100Mbps~300Mbps 以上的稳定吞吐。单线程性能的高低,直接反映了 Providers 向一级运营商采购的高优先级传输 Bandwidth 冗余。
2. 多线程测速的“伪繁荣”陷阱#
- 多线程工具(如默认模式下的 Speedtest、多线程下载器) Passed 开启 8 到 16 并发 TCP 连接切片传输。
- On a degraded route with 5% packet loss, each connection may achieve only 15Mbps, but 16 connections together can still total 240Mbps, creating the false impression that the route is healthy.
- Benchmark Conclusion: multithreaded tests only verify the physical bandwidth ceiling assigned to the VPS by the data center (Port Burst Cap); single-thread results are what truly represent the end user's experience.
Two. Key Testing Windows and Identifying Network Peak and Off-Peak Periods#
进行跨国性能量化测试,必须明确测试的时间窗口,脱离时段的数据没有任何横向 Compare 价值。
| Testing Window | International Submarine Cable and Backbone Status | Carrier QoS Policies | How to Interpret Speed-Test Results |
|---|---|---|---|
| Daytime Off-Peak (08:00 - 18:00) | Low International Egress Load and Minor Link Congestion | Low Packet Loss on Standard Routes Such as 163 and AS4837 | Use Only as a Reference for Network Adapter and Data Center Physical Limits, Not as a Basis for Plan Selection |
| Prime Evening Peak (20:00 - 23:30) | International Traffic Surges and Consumer Backbone Egress Links Reach Capacity | 触发多级 QoS 丢包限速,普通数据包被大量丢弃 | Primary Evaluation Window, providing a realistic test of route priority and high-availability disaster resilience |
| 深夜低谷期 (01:00 - 06:00) | 国际 Bandwidth 利用率最低 | No Throttling or Packet Loss, with Stable Peak Performance | Suitable for Testing the Host's Hardware CPU Performance and Raw NVMe Performance While Minimizing Network Interference |
When writing or recording a review report, clearly specify the local start and end timestamps (CST), your local carrier (such as China Telecom, China Unicom, or China Mobile), and your physical connection setup (such as a direct wired gigabit fiber connection).
Three. Pre-Test Environment Preparation and Provider Console Procedures#
Before stress testing, make sure instance networking, firewall rules, and management credentials are ready. Providers differ significantly in instance security policies and console architecture, and changing settings blindly can interrupt connectivity.
1. Login Credentials and Secure Connection Management#
- DMIT Instance Credential System:
- Default Security Policy: DMIT cloud instances disable remote root password login by default and strongly require the use of SSH key pairs during initialization.
- How Key Changes Take Effect: In the DMIT management console, public keys can be managed in the SSH Keys repository and in the instance's
Access选项卡中调整登录凭证。需要特别注意:After replacing the key in the control panel, you must reboot the instance through the panel (Reboot) before the new key is written to the system and takes effect。 - Emergency Access Channel: If SSH access is blocked because a local public key was lost or a firewall was misconfigured, open the following in the DMIT console:
Console(VNC/Web Console) for out-of-band maintenance and troubleshooting.
- BandwagonHost Credentials and Control Panel Features:
- Three Separate Password Systems: BandwagonHost's password system has three independent components: the client-area billing password, the dedicated KiwiVM management console password, and the instance operating system's
rootpassword. You must use KiwiVM's own credentials to log into its panel. - Out-of-Band Troubleshooting and Network Diagnostics: the KiwiVM panel includes
Interactive Console(Interactive Console), allowing you to enter single-user or rescue mode for recovery even if the network driver fails or the system firewall completely blocks SSH. - Data Center Migration and IP Status Constraints: BandwagonHost supports self-service data center migration in the client area, but its official knowledge base explicitly states:When the instance's currently assigned IP is on an unavailability blacklist, the console's data center migration (Migrate) feature is restricted. Before large-scale speed testing, first verify IP health through Ping and port scans from your local network.
- Three Separate Password Systems: BandwagonHost's password system has three independent components: the client-area billing password, the dedicated KiwiVM management console password, and the instance operating system's
2. Planning Speed-Test Traffic Within Refund Eligibility Limits#
International iperf3 stress tests and high-speed Speedtest runs can transfer tens of gigabytes (GB) in a very short time. If the current testing is part ofAcceptance Evaluation for a Newly Purchased Plan, pay close attention to the provider's Terms of Service (TOS) and traffic-usage limits for refunds:
- BandwagonHost Refund Traffic Limits:
- The official Terms of Service require refund requests for eligible new purchases to be submitted within 30 days.
- Critical Usage Limits: When requesting a refund, the service's usage during the billing cycleMonthly Traffic Usage Must Remain Strictly Below 10% of the Total Quota. If a plan with a 1000GB allowance uses more than 100GB during initial testing, refund eligibility is lost immediately. Once a refund is processed, the instance and all associated data are permanently destroyed.
- DMIT Refund Traffic and Time Limits:
- The official refund policy distinguishes full and partial refunds. For a full refund on an eligible new instance,Must Be Submitted Within 3 Days of Purchase, with Total Data Usage Not Exceeding 30GB。
- Refund requests after 3 days but within 30 days are eligible only for a partial refund of the remaining value after applicable deductions, with explicit exclusions where no refund is available.
- 此外,DMIT 不同 Series 的 Plan (如 Premium、Eyeball 等)具有不同的超量处理策略(部分为降速不断网,部分为停机或附加计费),应提前在 instance 详情页确认配额规则。
[!WARNING] 一次完整的 8 线程 iperf3 双向压测(跑满 1Gbps 持续 60 秒)将消耗约 15GB 数据流量。在进行机型验收测试时,切忌长时间盲目挂载压测脚本,务必先 compute 当前已消耗流量,避免超出商家的无损退款用量上限。
Four. Practical Operating Guidelines for Production-Grade Speed-Testing Tools#
For quantitative benchmarking, abandon outdated third-party Python speed-test scripts, whose interpreter performance and single-core overhead can become bottlenecks above 500Mbps, and use natively compiled binary tools instead.
1. Testing Guidelines for the Native Ookla Speedtest CLI Binary#
Install Ookla's official natively compiled Speedtest CLI on the target VPS:
# Ubuntu / Debian 官方软件源部署
curl -s https://packagecloud.io/install/repositories/ookla/speedtest-cli/script.deb.sh | sudo bash
sudo apt-get install -y speedtestCore Test Parameters and Commands#
- Single-Thread Testing (Essential Core Metric):
Use
-uor select single-connection mode to limit Speedtest to one TCP connection:# 强制单线程模式向默认最优节点测速 speedtest --single - Find and Specify Core Backbone Nodes in Mainland China:
The default speed-test server is often the geographically closest overseas node, which cannot measure the quality of the route back to China. List and select core hub nodes from China's three major carriers:
# 查询当前可用的临近与推荐节点列表 speedtest -L # 指定特定测速节点 ID 发起单线程测试(例如指定国内电信或联通骨干节点) speedtest -s <Node_ID> --single # 针对同一节点发起多线程压测(对照分析并发上限) speedtest -s <Node_ID>
Criteria for Interpreting the Output:#
- Latency(空闲时延)与 Jitter(抖动): Normal trans-Pacific fiber RTT between China and the United States should be between 130ms~170ms. If evening peak jitter consistently exceeds 20ms, the upstream interconnection route is congested.
- Low/High Latency (Latency Under Full Load, or Bufferbloat):观察在数据压榨阶段 ping 值的攀升幅度。优秀的高端优化 Networks (如 DMIT Pro 路由或 BandwagonHost DC6 联通回程)在满载时的延迟增幅通常小于 30ms。
Five. In-Depth End-to-End Network Stress Testing: iperf3 Operating Guidelines and Tuning#
Speedtest depends on public test servers' performance and outbound allowances, introducing the variable of third-party bandwidth limits. To measure the precise network capacity between your local operations client and the target VPS,iperf3 is an industry standard in network engineering.
[ 本地测试机 (Client) ] ── (公网端到端长肥管道) ──> [ 境外 VPS (Server) ]
发起定向单流/多流发包 监听指定端口 (默认 5201)1. VPS-Side Service Deployment and Security Configuration#
Deploy the iperf3 server on the target VPS:
# 安装 iperf3
sudo apt-get update && sudo apt-get install -y iperf3
# 以前台监听模式启动,并绑定测试端口(如 5201)
iperf3 -s -p 5201[!TIP] If a connection times out, check the firewall inside the system (
ufworiptables) allows both TCP and UDP traffic on port 5201. If firewall changes accidentally block your SSH port, use the provider's out-of-band console, such as BandwagonHost KiwiVM Interactive Console or DMIT Console, to log in and reset firewall rules.
2. 本地测试客户端的 Standard 评测矩阵#
After installing the iperf3 client on your local computer (macOS / Linux / Windows WSL), run the following three standardized tests in order:
Method A: Pure Single-Thread TCP Stress Testing During Evening Peak Hours (Baseline)#
# -c: 服务器 IP; -p: 端口; -t: 持续秒数(建议30s); -P 1: 强制单线程; -i 1: 每秒输出一次报告
iperf3 -c <VPS_IP> -p 5201 -t 30 -P 1 -i 1- What to Observe: In the output,
Retr(retransmitted packets). If retransmissions remain very low (< 50) during evening peak hours and single-thread throughput stays above 80Mbps, the route is not suffering the effects of backbone packet loss.
Method B: 8-Thread Concurrent Throughput Stress Test (Port Capacity Baseline)#
# 评估多连接并发状态下的聚合吞吐能力
iperf3 -c <VPS_IP> -p 5201 -t 30 -P 8 -i 1- What to Observe: Observe the combined bandwidth of the 8 streams (
SUM) can consistently approach the provider's specified physical speed limit.
Method C: Reverse Transfer Stress Test (Simulating Data Sent from the VPS to Your Local Machine)#
By default, the client sends data to the server, testing local upload / VPS download. To assess website access or file download performance, you must test the VPS's outbound download path to the user (VPS upload to the local machine):
# -R: 反向传输模式 (Reverse mode),由 VPS 向本地客户端发送数据流
iperf3 -c <VPS_IP> -p 5201 -t 30 -P 1 -R -i 1方案 D:UDP 抖动与真实丢包率精确量化#
TCP can conceal packet-loss details. Sending traffic at a fixed rate in UDP mode directly reveals the link's actual packet loss:
# -u: UDP 模式; -b: 目标设定带宽(如 50M); 观察丢包百分比
iperf3 -c <VPS_IP> -p 5201 -u -b 50M -t 20 -R- 判定基准:晚高峰优质 Networks 的 UDP 丢包率应维持在 1% 以下;普通骨干网 Networks 在高峰期丢包率经常飙升至 15%~30%。
Six. Comprehensive Host Hardware and Base Environment Benchmarking (YABS)#
Network throughput does not operate in isolation. The virtualization platform's CPU clock scheduling, core allocation, and disk I/O speed directly determine network interface softirq and packet-forwarding capacity.
The Industry's Most Authoritative Integrated Benchmarking Tool Is YABS(Yet Another Bench Script), which should be run as soon as the new server is deployed:
# 执行完整 YABS 测试(包含硬件信息、磁盘 FIO、全球多节点网络与 Geekbench 跑分)
curl -sL https://yabs.sh | bash
# 若实例内存低于 1GB,为避免触发 OOM 杀进程,可使用参数跳过高负荷 Geekbench:
curl -sL https://yabs.sh | bash -s -- -gEngineering Interpretation of Key Output Metrics:#
- FIO Disk Performance (4k Random and 1m Sequential Read/Write):
4kRandom read/write performance should remain above 20,000 IOPS. During high-frequency cross-border data writes, excessive disk queue buildup can prevent network buffers from flushing to disk promptly, causing packet loss.1mSequential read/write: high-quality enterprise NVMe arrays typically deliver read/write speeds between 1,000 MB/s and 2,500 MB/s.
- Geekbench CPU Benchmark Score:
- Single-Core performance is the key metric governing high-throughput TLS/AES encryption and the ceiling for single-thread TCP processing. Modern AMD EPYC processors generally score above 1,300 per core, ensuring that CPU soft interrupts do not saturate at 1Gbps throughput.
Seven. A Framework for Summarizing Test Reports and Aligning with Long-Term Operations#
A rigorous VPS performance and network evaluation should ultimately produce standardized, structured logs to support comparisons and technical decisions.
1. Standard Review Report Recording Template#
### VPS 实例基准测试记录表
- **服务商与机型**:[填写商户名称及产品线,如 BandwagonHost / DMIT]
- **测试时间窗口**:2026-09-26 21:15 - 22:30 (晚高峰 CST)
- **本地接入网络**:中国联通 1000M 光纤直连 (上海)
- **目标服务器配置**:1 vCPU / 1GB RAM / NVMe
- **系统核心拥塞算法**:BBR (sysctl net.ipv4.tcp_congestion_control)
#### 核心网络实测数据
1. **本地端到端 (iperf3)**:
- 单线程下载 (-R -P 1): 215 Mbps (重传数: 12)
- 8 线程下载 (-R -P 8): 910 Mbps (打满端口上限)
- UDP 丢包率 (50M 压力): 0.3%
2. **Speedtest CLI (国内指定骨干节点)**:
- 联通核心节点 (单线程): 下行 240 Mbps / 上行 180 Mbps / 抖动 3.2ms
- 电信核心节点 (单线程): 下行 190 Mbps / 上行 150 Mbps / 抖动 5.1ms
3. **硬件支撑指标 (YABS)**:
- FIO 4k 混合读写 IOPS: 32,400
- Geekbench 6 单核评分: 1,4202. Aligning Test Instance Lifecycles and Billing#
在完成机型性能验证并决定长期保留该 instance 作为生产节点后,必须将评测阶段的“临时维护心态”切换为“生产运维合规”,并关注两家 Providers 在财务与数据生命周期上的差异:
- Invoice Generation and Expiration Handling Policies:
- BandwagonHost: The official knowledge base explicitly states that the systemDoes Not Silently Charge a Linked Credit Card or PayPal Account. If renewal is enabled, an invoice is usually generated 7 days before the service expires. The system automatically applies account credit only if the user has prepaid a sufficient balance. After testing is complete, keep an eye on billing notification emails or add funds to the account to prevent service suspension for nonpayment.
- DMIT: The Docs billing rules state that monthly renewal invoices are also generated 7 days before expiration. Once nonpayment puts the service into Suspended status,The System Generally Retains Only About a 3-Day Grace Period;逾期未结清账单, instance 及其挂载的磁盘数据将被永久销毁,无法恢复。
- Network Baseline Retesting Process:
Cross-border submarine cables and upstream carrier peering routes are frequently adjusted dynamically. The goal of standardized speed testing is not a one-off screenshot, but to turn the above
iperf3 -P 1andspeedtest --singleSchedule it as a regular, lightweight monitoring task that avoids high loads, such as collecting a baseline once a week outside business hours with a scheduled script. This provides solid historical data to isolate faults and support service-quality claims if network quality silently deteriorates or upstream routes change.